Swimlane AI Agents Case Management Extension
Overview
The Swimlane AI Agents Case Management Extension provides a unified set of Hero AI agents with a user interface that accelerates SOC analyst workflows for triage, investigation, and incident response. The extension includes three specialized Hero AI agents that work together to maximize analyst efficiency and reduce mean-time-to-respond (MTTR).
You can manage these AI agents in the following ways:
- Enable automatic analysis for all alerts
- Disable analysis entirely
- Run analysis selectively based on playbook criteria
- Use the Run Hero AI Analysis button for on-demand analysis on individual cases
Prerequisites: Install the SOC Solution in Swimlane Turbine before installing the AI Agents Case Management Extension.
How It Works
The AI Agents Case Management Extension integrates with the Case and Incident Management (CIM) application in the SOC Solutions Bundle. When a signal is created in CIM, you can trigger Hero AI analysis automatically or manually to get comprehensive security insights.
The extension processes cases as follows:
- Receives a tracking ID from the CIM application for a case or signal
- Executes multiple Hero AI analyses in parallel or sequence:
- Signal Verdict and Threat Intelligence Analysis
- MITRE ATT&CK & D3FEND Analysis
- Complete Signal Analysis
- Returns enriched results to the same CIM record with actionable insights
The extension includes the Hero AI SOC Extension applet, which provides a user interface for viewing and interacting with AI-generated analysis results directly within case records.
What's Included
The AI Agents Case Management Extension includes the following components:
- Hero AI SOC Extension applet for displaying analysis results in CIM cases
- On Demand Hero AI Analysis playbook for manual analysis triggers
- Automated Hero AI Analysis flow for automatic analysis on alert ingestion
- Four specialized builder components (see Components section)
- Automated_Hero_AI_Analysis sensor for automated triggering
- SOC_Solution_Hero_AI_Configuration data object asset for configuration
- Support fields for storing analysis results and driving the widget
Components
The extension includes the following Builder Components:
HASE - Hero AI Analysis
Description: Orchestrates all three Hero AI analyses (Signal Verdict and Threat Intelligence, MITRE Analysis, and Complete Signal Analysis) and returns the results to the CIM record.
Inputs:
- Tracking ID from the CIM Application
Outputs:
- Hero AI analysis results written back to the CIM record
Usage: This is the main component that should be called to perform comprehensive Hero AI analysis on a case.
HASE - Hero AI Signal Verdict and Threat Intelligence Analysis
Description: Performs detailed threat analysis by autonomously correlating and weighting threat intelligence from multiple sources.
Capabilities:
- Case classification (Benign, Suspicious, or Malicious)
- AI confidence score (0-10) based on threat intelligence correlation
- Source correlation from multiple threat intelligence providers
- User-defined weighting for providers and observable types
- AI-generated summary analysis
HASE - Hero AI Complete Signal Analysis
Description: Provides comprehensive signal analysis including immediate verdict, severity rating, and actionable recommendations.
Capabilities:
- Visual severity rating and verdict
- NIST-aligned action recommendations
- AI confidence score and data correlation
- Automated case title generation
- Affected entities visualization
HASE - Hero AI MITRE Analysis
Description: Maps and enriches MITRE ATT&CK TTPs (Tactics, Techniques, and Procedures) and provides D3FEND defensive recommendations.
Capabilities:
- Automatic T-Code mapping from security alerts
- Contextual enrichment using threat intelligence
- MITRE D3FEND defensive recommendations
- Enhanced threat context for security reports
Extract - Parse JSON from Text
Description: Utility component for parsing JSON data from text fields, used by other Hero AI components.
Hero AI Agents
The extension is driven by three specialized Hero AI Agents:
1. Investigation Agent
Purpose: Provides immediate visual verdict, severity, and actionable recommended actions for every security case.
Capabilities:
- Visual Severity Rating & Verdict: Displays immediate severity and case verdict (Malicious, Suspicious, or Benign) for quick prioritization
- NIST-Aligned Action Recommendations & Validation Checks: Provides clear, actionable response steps aligned with NIST Cybersecurity Framework phases (Containment, Eradication, Recovery) and associated validation checks
- AI Confidence Score & Data Correlation: Provides a quantifiable confidence level (0-10) by correlating data from:
- Knowledge Base articles
- Historical learning from past cases
- Current case details and context
- Automated Case Title & Affected Entities Visual: Automatically generates a concise, descriptive case title and visually highlights affected assets/users for quick identification
Use Cases:
- Initial case triage and prioritization
- Quick severity assessment
- Automated case documentation
- Affected entity identification
2. Verdict and Threat Intelligence Analysis Agent
Purpose: Delivers an investigation case summary and final threat classification, assigning a quantifiable AI confidence score based on deep data correlation.
Capabilities:
- Case Classification & Hero AI Confidence Score:
- Classifies the case as Benign, Suspicious, or Malicious
- Provides a quantifiable confidence score (0-10) based on threat intelligence correlation
- AI-Generated Summary: Provides a comprehensive summary analysis of the case
- Data Correlation: Uses a wide range of data points including:
- Knowledge articles from your knowledge base
- Historical outcomes from similar cases
- Correlated manual verdicts from analysts
- Threat Intelligence Integration: Incorporates data from intelligence sources including:
- VirusTotal
- Recorded Future
- Mandiant
- AbuseIPDB
- URLHaus
- Customer-connected 3rd party feeds
- Source Correlation: Correlates intelligence from multiple sources and provides weighted analysis
- User-Defined Weighting: Allows users to define and change:
- Threat intelligence providers
- Observable types (IP, domain, hash, URL, etc.)
- Weights in the threat formula
Use Cases:
- Deep threat analysis and classification
- Threat intelligence correlation
- Case verdict determination
- Confidence-based prioritization
3. MITRE ATT&CK & D3FEND Agent
Purpose: Maps and enriches associated TTPs (Tactics, Techniques, and Procedures) to enhance threat context, providing appropriate defensive D3FEND recommendations.
Capabilities:
- T-Code Mapping: Automatically maps MITRE ATT&CK TTPs (T-Codes) using:
- Pre-existing data from the 3rd party security alert
- Contextual enrichment from Hero AI analysis
- Contextual Enrichment: Hero AI further enriches the mapping using:
- Intelligence from other security cases
- Current threat feeds
- Internal knowledge base articles
- Defense Recommendations: Automatically includes MITRE D3FEND recommendations in:
- The output analysis
- Security reports
- Proactive defensive actions
Use Cases:
- Threat actor technique identification
- Attack pattern mapping
- Defensive strategy recommendations
- Security report generation
- Threat hunting preparation
Installation
Prerequisites
Before you install the extension, ensure the following:
- The SOC Solutions Bundle is installed in your Turbine instance
- The Case and Incident Management (CIM) application is configured and operational
- Hero AI is enabled and configured in your Turbine instance
Installation Steps
Install from Library
To install the extension:
- Navigate to the Swimlane Content Library from your tenant
- Click Library
- Click Swimlane Content
- Find and select AI Agents Case Management Extension from the list of solutions
- Click Install Note: If content already exists in your environment, you may be prompted to overwrite it. To avoid overwriting content, deselect items you don't want to overwrite. If you deselect too many required items, the solution won't install completely.
- Enable the playbooks that were installed with the extension
- Verify the installation:
- Confirm the Hero AI SOC Extension applet appears in your CIM application
- Verify all builder components are available in Canvas
- Check that the Automated_Hero_AI_Analysis sensor is configured
After installation, integrate the extension into the Case and Incident Management solution.
Integration
Add the Applet to the CIM Application
To add the Hero AI SOC Extension applet to your CIM application:
- Open the Case and Incident Management (CIM) application
- Open the application editor
- Drag the Hero AI SOC Extension applet to the case record layout
- Save the application layout
Add the On-Demand Analysis Button
To enable manual Hero AI analysis, add a button to trigger the analysis:
- In the CIM application editor, add a new button
- Name the button Analyze with Hero AI or Run Hero AI Analysis
- Configure the button action:
- Select the HASE playbook
- Select On Demand Hero AI Analysis as the playbook flow
- Save the button configuration
Note: The On Demand Hero AI Analysis playbook is installed with the extension and doesn't require additional configuration.
Configuration
Configure Included Assets
To use third-party tools for enrichment and analysis, configure the assets for the tools you want to use.
To configure assets:
- Navigate to Orchestration > Assets
- Configure all supplied assets for third-party technologies you want to use:
- VirusTotal
- Recorded Future
- Abuse.ch
- URLHaus
- IPQualityScore
- Other threat intelligence providers
Configure Custom Assets
The extension includes custom assets that let you configure variables used in playbooks or components without editing the playbooks or components directly.
SOC_Solution_Hero_AI_Configuration Asset
The SOC_Solution_Hero_AI_Configuration asset (also called the HASE asset) contains the following configuration options:
- Threat Intelligence Weights: Configure weights for your threat intelligence providers. Weights use a sliding scale and can be any number. Weights are relative to each other. For example, if one provider has a weight of 10 and another has 5, the first provider has twice the influence. To add new threat intelligence providers, add them to the threat_intelligence_weights variable.
- Auto Analysis: Enable or disable automated Hero AI analysis. This is set to false by default to prevent automatic analysis until you enable it. Set this to true after you configure the automated flow (see Automated Flow Configuration).
- Similar Records Match Percentage Threshold: Set the similarity threshold for finding similar records. Lower values return more similar records. Higher values return fewer but more closely matched records. Adjust this based on your data. If records are typically not very similar, lower this value to see results.
TI Primary Intelligence Providers Asset
To change the primary provider for any threat intelligence types, configure them in this asset. Ensure that valid and configured enrichment sources exist for the providers you select.
Configure Automated Flow
To enable automated Hero AI analysis when new alerts are ingested, configure the SOC Solution playbook to emit an event that triggers the Hero AI analysis flow.
To configure the automated flow:
- Open your SOC Solution playbook in Canvas
- Find the Get Completed Observables Status flow, which marks the end of the case ingestion lifecycle
- Find the update action that occurs after observable completion
- After that update action, add an Emit Event action:
- Select Emit to Hero AI Analysis
- Select Existing Flow Event
- Select Automated Hero AI Analysis Important: After adding the event emitter, you may not see the event in the dropdown immediately. This is a known platform bug. To work around it:
- Save the playbook
- Reload or refresh the page
- The events should now appear in the dropdown
- Configure the emitter to pass the Tracking ID from the record event trigger
- After you configure the event emitter, enable automated analysis by setting the Auto Analysis toggle to true in the SOC_Solution_Hero_AI_Configuration asset
How automated analysis works:
When a new alert comes in:
- It goes through the normal SOC Solution ingestion flow
- Observable processing completes
- The "Automated Hero AI Analysis" event is emitted
- The Hero AI analysis flow is triggered automatically
- Analysis runs through the Hero AI analysis component
If you set Auto Analysis to false, the automated flow is disabled and analysis runs only when you trigger it manually via the button.
Component Configuration
The extension includes several Builder Components that follow a similar pattern: they collect data, use an AI prompt, parse the output, and return results. Most components do not require editing, but there are optional configuration points:
HASE - Hero AI Analysis Component:
- Main orchestration component that calls the other analysis components
- Generally does not require editing
- Contains the overall flow logic
HASE - Hero AI Signal Verdict and Threat Intelligence Analysis Component:
- Handles signal and threat intelligence verdict analysis
- Optional Configuration: If you need to edit the AI prompt, it lives in the "Hero AI Analysis" section at the bottom of the component
- The prompt includes variables that get populated from KBAs, threat intelligence research, similar signals, and other data sources
- Generally does not require editing unless you want to customize the prompt
HASE - Hero AI MITRE Analysis Component:
- Maps and enriches MITRE ATT&CK techniques
- MITRE Data Sources:
- Primary: Looks for MITRE ATT&CK techniques in the MITRE Attack Techniques field in the SOC Solution
- Alternative: Can extract T-codes (like T1001.123) from the raw alert if they're not mapped to the field
- Optional Configuration:
- To extract T-codes from raw alerts, go to "Get Current Record" action and add the raw event field
- This will automatically scan the raw alert for T-codes
- Note: Mapping the raw event causes a large increase in token usage, but it's useful if you're having trouble extracting MITRE data normally
- Generally does not require editing unless you need to extract T-codes from raw alerts
HASE - Hero AI Complete Signal Analysis Component:
- Provides recommendations and complete signal analysis
- Can also map in the raw alert, but there's generally not a good reason to do so
- Generally does not require editing
Component Pattern: All components follow the same pattern:
- Collect data from the case record
- Use an AI prompt with variables
- Parse the prompt output
- Return structured results
You typically don't need to edit these components unless you want to customize the prompts or add additional data sources.
Usage
Trigger Manual Analysis
To manually trigger Hero AI analysis for a case:
- Open a case or signal in the CIM application
- Click the Analyze with Hero AI button (or the name you configured)
- Wait for analysis to complete (typically 1-2 minutes; AI prompts take longer than standard integrations)
- Review the results in the Hero AI SOC Extension applet
Data collection:
When you trigger Hero AI analysis, it collects the following data from the case record:
- All case data and context
- Linked Knowledge Base Articles (KBAs)
- Threat intelligence observables associated with the case
- MITRE ATT&CK techniques (if present in the case)
- Similar records from historical cases
- Other relevant case metadata
This data collection enables the AI agents to provide accurate verdicts and recommendations.
Automated Analysis
Automated analysis runs automatically when new alerts are ingested, provided you have:
- Configured the event emitter in your SOC Solution playbook (see Automated Flow Configuration above)
- Set the Auto Analysis toggle to true in the SOC_Solution_Hero_AI_Configuration asset
When automated analysis is enabled, every new alert that completes the observable ingestion lifecycle will automatically trigger Hero AI analysis without manual intervention.
Playbook Integration
Use the Hero AI components in your playbooks:
Workflow Integration
The extension integrates with the SOC Solutions Bundle workflow:
Integration Points
- Alert Triage Solution: Hero AI analysis can be triggered automatically when alerts are triaged
- Phishing Triage Solution: Analysis can run on phishing email signals
- Threat Intelligence Solution: Results incorporate TI enrichment data
- Case and Incident Management: Analysis results are displayed in case records
Output and Results
Analysis Results Structure
Each Hero AI analysis returns structured results displayed in the Hero AI SOC Extension applet:
Verdict Analysis:
- Verdict: Malicious, Suspicious, or Benign classification
- Verdict Confidence Score: Separate confidence score specific to the verdict analysis
- Overall Confidence Score: Aggregate confidence score (0-10) that includes all analyses (verdict, threat intelligence, MITRE, and remediation actions)
- Total Verdict: Final classification based on all analyses
Threat Intelligence Analysis:
- Threat intelligence correlation results
- Confidence score specific to threat intelligence analysis (may differ from verdict confidence)
- Source attribution from multiple threat intelligence providers
MITRE ATT&CK Analysis:
- MITRE ATT&CK technique mappings (displayed as boxes, one per technique)
- Each technique box includes:
- Technique information
- Defensive recommendations (D3FEND) for that technique
- Note: MITRE analysis does not have a separate confidence score
Recommended Actions:
- NIST-aligned action recommendations (Containment, Eradication, Recovery)
- Copy to Playbook button
- Copy to Clipboard button (intended for pasting into Hero AI Companion for blocking actions)
Similar Records Widget:
- Displays the top 10 records that Hero AI found similar to the current case
- Shows metadata about each similar record in a table format
- These records are not linked (not reference fields) - they're informational only
- Used by Hero AI as context when determining verdict and confidence scores
Support Fields:
- Hero AI Verdict: Contains the verdict data (used for orchestration/reporting)
- Hero AI Verdict Confidence: Contains the verdict confidence score (used for orchestration/reporting)
- Overall Confidence: Contains the overall confidence score (used for orchestration/reporting)
- These fields drive the widget display and can be used for playbook orchestration or reporting purposes
Widget Display:
- The Hero AI SOC Extension applet includes a widget that displays all analysis results
- The widget is automatically populated when analysis completes
- You generally don't need to edit the widget - it's configured to display results correctly
- The widget shows verdict, confidence scores, recommendations, MITRE techniques, and similar records
Understanding Confidence Scores
It's important to understand that there are multiple confidence scores:
- Verdict Confidence Score: Specific to the verdict analysis
- Threat Intelligence Confidence Score: Specific to the threat intelligence correlation
- Overall Confidence Score: Aggregate score that combines all analyses including remediation actions, verdict, threat intelligence, and MITRE analysis
The overall confidence score represents Hero AI's confidence in all the work it has done, not just the verdict.
Best Practices
When to Use Hero AI Analysis
- High-Volume Alerts: Use automated analysis to triage large volumes of alerts
- Complex Cases: Request analysis for cases requiring deep investigation
- Knowledge Gaps: Use analysis when analyst expertise is limited on specific threat types
- Consistency: Ensure consistent analysis approach across all cases
Optimization Tips
- Configure Provider Weights: Adjust threat intelligence provider weights based on your organization's trusted sources
- Review Confidence Scores: Use confidence scores to prioritize analyst attention
- Combine with Manual Analysis: Use Hero AI as a starting point, not a replacement for analyst judgment
- Update Knowledge Base: Regularly update knowledge base articles to improve AI accuracy
- Monitor Performance: Track analysis accuracy and adjust configurations as needed
Performance Considerations
- Analysis typically completes in 1-2 minutes per case (longer than standard integrations because it uses AI prompts)
- Multiple analyses can run in parallel for different cases
- Consider rate limits when enabling automated analysis for high-volume environments
- Mapping raw events for MITRE T-code extraction significantly increases token usage - only use this if necessary
- Cache results when appropriate to reduce redundant analysis
Troubleshooting
Common Issues
Issue: Hero AI analysis not triggering
- Solution: Verify the Hero AI SOC Extension applet is installed in the CIM application
- Solution: Check that Hero AI is enabled in your Turbine instance
- Solution: Verify component dependencies are properly configured
Issue: Low confidence scores
- Solution: Ensure threat intelligence providers are properly configured
- Solution: Review knowledge base articles for relevant content
- Solution: Check that case data includes sufficient observables and context
Issue: Missing threat intelligence data
- Solution: Verify threat intelligence providers are connected and operational
- Solution: Check provider API keys and rate limits
- Solution: Review observable extraction from alerts and emails
Issue: MITRE ATT&CK mappings incomplete
- Solution: Ensure source alerts include MITRE ATT&CK data in the MITRE Attack Techniques field
- Solution: If T-codes (like T1001.123) are in the raw alert but not mapped to the field, configure the MITRE component to extract from raw event (see Component Configuration section)
- Solution: Verify knowledge base contains relevant attack pattern information
- Solution: Check that Hero AI has access to current MITRE ATT&CK framework data
Issue: Event emitter not appearing in dropdown after adding to SOC Solution playbook
- Solution: This is a known platform bug. Save the playbook, reload/refresh the page, and the events should appear in the dropdown
- Solution: This bug is expected to be fixed in a future release, but not in the upcoming release
Issue: Automated analysis not running
- Solution: Verify the event emitter is properly configured in your SOC Solution playbook
- Solution: Ensure the "Auto Analysis" toggle is set to true in the SOC_Solution_Hero_AI_Configuration asset
- Solution: Check that the event emitter is placed after the observable completion update action
- Solution: Verify the Tracking ID is being passed correctly from the record event trigger
References
- SOC Solutions BundleSOC Solutions Bundle